X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=config%2Fnagios-master.cfg;h=0f0c21eea1324d329aa001315c69eefb631fcea3;hb=5cc57cb7c2c7d167b21efdd86b63590438ea0190;hp=cb9c73cf2a83287433f635aa13bc26e8ecaba9cd;hpb=9f238fc9fc1f7fb86abda3f00a7bd7fe9decb158;p=mirror%2Fdsa-nagios.git diff --git a/config/nagios-master.cfg b/config/nagios-master.cfg index cb9c73c..0f0c21e 100644 --- a/config/nagios-master.cfg +++ b/config/nagios-master.cfg @@ -323,7 +323,7 @@ servers: bm-bl9: address: 5.153.231.249 parents: gw-bytemark - hostgroups: computers, bm-bl, acpid-hosts, service, wheezy, openstack-compute, broken_mq + hostgroups: computers, bm-bl, service, jessie bm-bl10: address: 5.153.231.250 parents: gw-bytemark @@ -348,7 +348,7 @@ servers: milanollo: address: 5.153.231.2 parents: gw-bytemark - hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, nfs-server, xinetd-hosts + hostgroups: computers, service, kvmdomains, jessie, apache2-hosts, apache-https, nfs-server, xinetd-hosts milanollo2: address: 5.153.231.9 parents: milanollo @@ -398,7 +398,7 @@ servers: philp: address: 5.153.231.13 parents: ganeti-bytemark - hostgroups: computers, hassrvfs, kvmdomains, jessie, apache2-hosts + hostgroups: computers, hassrvfs, kvmdomains, jessie, apache2-hosts, apache-https rainier: address: 5.153.231.16 parents: ganeti-bytemark @@ -410,7 +410,7 @@ servers: delfin: address: 5.153.231.17 parents: ganeti-bytemark - hostgroups: computers, hassrvfs, kvmdomains, jessie, apache2-hosts, nfs-client, autofs + hostgroups: computers, hassrvfs, kvmdomains, jessie, apache2-hosts, apache-https, nfs-client, autofs wuiet: address: 5.153.231.18 parents: ganeti-bytemark @@ -440,7 +440,7 @@ servers: petrova: address: 5.153.231.25 parents: ganeti-bytemark - hostgroups: computers, kvmdomains, jessie, apache2-hosts + hostgroups: computers, kvmdomains, jessie, apache2-hosts, apache-https oyens: address: 5.153.231.26 parents: ganeti-bytemark @@ -668,7 +668,7 @@ servers: mirror-isc: address: 149.20.20.7 parents: gw-isc - hostgroups: computers, service, apache2-hosts, dl360, hpnewraid, hassrvfs, xinetd-hosts, jessie, security_mirror + hostgroups: computers, service, apache2-hosts, apache-https, dl360, hpnewraid, hassrvfs, xinetd-hosts, jessie, security_mirror mirror-isc2: address: 149.20.20.19 parents: mirror-isc @@ -807,7 +807,7 @@ servers: wolkenstein: address: 82.195.75.65 parents: ganeti3 - hostgroups: computers, hasbootfs, hassrvfs, kvmdomains, service, xinetd-hosts, rsyncd-hosts, apache2-hosts, jessie + hostgroups: computers, hasbootfs, hassrvfs, kvmdomains, service, xinetd-hosts, apache2-hosts, jessie, apache-https mipsel-manda-01: address: 82.195.75.72 parents: gw-man-da @@ -1022,7 +1022,7 @@ servers: tye: address: 206.12.19.129 parents: ganeti2 - hostgroups: computers, service, kvmdomains, jessie, heavy-exim, apache2-hosts, nfs-client, autofs, hassrvfs + hostgroups: computers, service, kvmdomains, jessie, heavy-exim, apache2-hosts, apache-https, nfs-client, autofs, hassrvfs elgar: address: 206.12.19.130 parents: ganeti2 @@ -1070,7 +1070,7 @@ servers: mirror-umn: address: 128.101.240.212 parents: gw-umn - hostgroups: computers, service, apache2-hosts, dl360, hpnewraid, hassrvfs, xinetd-hosts, jessie, security_mirror + hostgroups: computers, service, apache2-hosts, apache-https, dl360, hpnewraid, hassrvfs, xinetd-hosts, jessie, security_mirror mirror-umn2: address: 128.101.240.215 parents: mirror-umn @@ -1106,7 +1106,7 @@ servers: klecker: address: 130.89.148.10 parents: gw-utwente - hostgroups: computers, service, apache2-hosts, rsyncd-hosts, dl380, xinetd-hosts, jessie, incomingmailrelayed2025, hassrvfs + hostgroups: computers, service, apache2-hosts, apache-https, rsyncd-hosts, dl380, xinetd-hosts, jessie, incomingmailrelayed2025, hassrvfs klecker-ftp: address: 130.89.148.12 parents: klecker @@ -2022,10 +2022,15 @@ services: nrpe: "if [ -e /var/lib/dsa/sso/ca.crl ]; then /usr/lib/nagios/plugins/dsa-check-crl-expire -w 129600 -c 86400 /var/lib/dsa/sso/ca.crl; else echo 'No sso/ca.crl on this host.'; fi" hostgroups: computers - - name: letsencrypt SSL certs + name: SSL certs - puppet hosts: global - remotecheck: "/srv/letsencrypt.debian.org/bin/check-cert-expire" - runfrom: denis + remotecheck: "/usr/lib/nagios/plugins/dsa-check-cert-expire-dir /etc/puppet/modules/ssl/files/servicecerts" + runfrom: handel + - + name: SSL certs - LE + hosts: global + remotecheck: "/usr/lib/nagios/plugins/dsa-check-cert-expire-dir /etc/puppet/modules/ssl/files/from-letsencrypt" + runfrom: handel # }}} # {{{ HW health/raid -